Can Dynamic Groups show indirect members by default instead having to enable checkbox "Show indirect members":
1. Open the Registry Editor by navigating to Start | Run and type regedit.
2. Navigate to the registry key HKEY_LOCAL_MACHINE\SOFTWARE\One Identity\Active Roles.
3. Create a new DWORD entry named BypassValidationForMatchingRuleOID and set the value to '1'.
Note: If multiple instances of ARS service is configured then Registry entry should be created in all Server hosts.
4. Create Custom LDAP search filter to include nested group members as direct members of the Dynamic group
5. Add a custom Ldap (memberof:1.2.840.1135126.96.36.1991:=CN=Groups,DC=domain,DC=local)
6. Now Members tab of the Dynamic group shows both direct and indirect members without clicking Show Indirect Members.
A list of more examples can be found in this link
For further information about LDAP_MATCHING_RULE_IN_CHAIN check out the links below.